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Abstract: We propose a method to improve the performance of two entanglement-based 
continuous-variable quantum key distribution protocols using noiseless linear amplifiers. 
The two entanglement-based schemes consist of an entanglement distribution protocol 
with an untrusted source and an entanglement swapping protocol with an untrusted relay. 
Simulation results show that the noiseless linear amplifiers can improve the performance of 
these two protocols, in terms of maximal transmission distances, when we consider small 
amounts of entanglement, as typical in realistic setups. 
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1. Introduction 

Quantum key distribution (QKD) [1,2] is the most practical application in the field of quantum 
information and enables two distant parties, Alice and Bob, to establish a secret key through 
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insecure quantum and classical channels. The continuous-variable version of quantum key distribution 
(CV-QKD) [3-5], an alternative to single-photon-based QKD, has attracted much attention in the 
past few years [5,6], mainly because it does not require single-photon sources or detectors. The 
Gaussian-modulated CV-QKD protocols based on coherent states [7-9] have been experimentally 
demonstrated [6, 10-12] and have been shown to be secure against arbitrary attacks in the asymptotic [13] 
and finite-size regimes [14]. Two-way protocols [15-18] and thermal-state protocols [19-21] have been 
also designed. 

However, there still exists a gap between the theoretical security analyses and the practical 
implementations. Such real-life implementations of CV-QKD systems may contain overlooked 
imperfections, which might not have been accounted for in the theoretical security proofs, and may 
provide security loopholes. Recently, various attacks have been proposed and closed, such as wavelength 
attacks [22-24], calibration attacks [25] and local oscillator fluctuation attacks [26]. One approach to 
overcome device imperfections is by characterizing the whole practical system and to consider all of the 
existing loopholes. Although some potential loopholes have been discovered and then closed using this 
approach, it is difficult to find all of the loopholes in practical CV-QKD systems, because the number of 
loopholes is theoretically infinite. 

Another approach is by establishing a full device-independent CV-QKD protocol like its 
discrete-variable counterpart [27], which is based on the violation of a Bell inequality [28]. Recently, 
there has been work to build various device-independent CV-QKD protocols, including schemes which 
are both one-sided [29] and fully device independent [30]. The goal of full device-independent QKD is 
the removal of the requirement that Alice and Bob need to trust their devices. 

In this paper, we consider two kinds of entanglement-based CV-QKD protocols in untrusted 
scenarios: an entanglement distribution protocol with an untrusted source and an entanglement swapping 
protocol with an untrusted relay. The latter protocol is inspired by [31] and corresponds to the 
entanglement-based version of the CV-QKD protocols described in [32-35]. In particular, we consider 
a symmetric formulation where the two legitimate partners both modify their data during the classical 
data post-processing stage. 

To improve the maximal transmission distances of these two schemes, we consider the use of two 
noiseless linear amplifiers (NLAs) [36], one at Alice’s side and one at Bob’s side. We show that the 
practical example of the CV-QKD protocol with an untrusted source, i.e., the entanglement-in-the-middle 
protocol [37], improves by placing two NLAs at the output of the quantum channel at both Alice’s and 
Bob’s side. Additionally, the maximal transmission distances of the untrusted relay scheme are also 
improved using this same method. Previously, a similar method had only been analysed for the case 
of the one-way CV-QKD protocol [38^0]. These improvements are found in the regime of small 
entanglement, which is typical in realistic implementations. It is also found that placing only one 
NLA at the non-reconciliation side (Alice’s side for reverse reconciliation and Bob’s side for direct 
reconciliation) has a greater improvement than placing it at the opposite side. 

This paper is organized as follows. In Section 2, we introduce the two entanglement-based CV-QKD 
protocols. In Section 3, we show that we can improve the performance of these protocols by using NLAs. 
Our conclusions are drawn in Section 4. 
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2. Entanglement-Based CV-QKD Protocols 

In this section, we begin by describing the two entanglement-based CV-QKD protocols: 
entanglement-based protocols with an untrusted source and entanglement-based protocol with an 
untrusted relay, which can also be thought of as entanglement distribution and entanglement swapping 
protocols, respectively. We then outline the secret key rates for these protocols in the presence of 
collective Gaussian attacks. 

2.1. Entanglement Distribution: Entanglement-Based Protocols with an Untrusted Source 

The schematic of the entanglement-based CV-QKD protocol with an untrusted source is illustrated in 
Figure 1 and can be described as follows: 

Step 1: The untrusted third party, Charlie, initially prepares an entangled source. He sends one mode 
Ai to Alice through Channel 1 and sends the other mode Bi to Bob through Channel 2, where Eve may 
perform her attack. 

Step 2: Alice and Bob perform either a homodyne (switching) (Horn) or a heterodyne (no switching) 
(Het) measurement on the received modes A 2 and B 2 . Once Alice and Bob have collected a sufficiently 
large set of correlated data, they proceed with classical data post-processing, namely error reconciliation 
and privacy amplification. The reconciliation can be performed in one of two ways: either direct 
reconciliation (DR) [7] or reverse reconciliation (RR) [8]. 



Figure 1. Schematic of the continuous-variable version of quantum key distribution 
(CV-QKD) protocols with an untrusted source. Both the entangled Gaussian source and 
the quantum channels are fully controlled by Eve. However, Eve has no access to the 
apparatuses in Alice’s and Bob’s stations. Alice and Bob can perform either homodyne 
(Horn) or heterodyne (Het) detection, using either direct or reverse reconciliation. 

Since the untrusted Charlie could be completely controlled by the eavesdropper, the original source 

in) 

PaiBi (where n denotes the number of quantum signals exchanged during the protocol) is not important 
to Alice and Bob. What matters is the final state PA 2 B 2 before their measurements. Here, we assume that 
the final state p\^b 2 ^ ‘collective source’ to simplify the problem, which means Alice and Bob get the 

same quantum state PA 2 B 2 ^^ch time, so that p^ 21 b 2 ^ Pmb 2 - asymptotic secret key rates K^r for 
direct reconciliation and Rjir for reverse reconciliation are given by [41]: 


KDR = PnA:B)-xiA:E) 
Krr = PI{A-.B)-x{B-.E) 


(1) 
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where P G [0,1] is the reconciliation efficiency, I (A : B) is the classical mutual information between 
Alice and Bob, x(A : E) and x{B : E) are the Holevo quantities [42]; 

{ X(A : E) = S(pe)-Y,^p(x)S(pe\,) 
\x(B:E)=S(pE)-j:,P(y)S(PE,y} ’ 

where S{p) is the von Neumann entropy of the quantum state p, x and y are Alice’s and Bob’s 
measurement results obtained with probability p (x) and p (y), pe\x and pE\y are the corresponding state 
of Eve’s ancillas and pe = Pe\x and pe = J^yPiv) PE\y are Eve’s average states for DRand 

RR, respectively. Unless both Alice and Bob performed heterodyne measurements, they first apply a 
sifting process, where they compare the chosen measurement quadrature {x or p) and only keep the data 
for which the quadratures match. Here, we use x and y to represent Alice’s and Bob’s measurement 
results, respectively, for both homodyne and heterodyne measurements. 

Note that these secret key rates could be modified to take finite-size effects into consideration. For 
simplicity, here we only consider the asymptotic secret key rates, i.e., achieved in the limit of infinite 
rounds of the protocol. Firstly, Eve is able to purify the whole system PA 2 B 2 to maximize her information, 
i.e., we have S (pe) = S {pa 2 B 2 )- Secondly, after Alice’s projective measurement resulting in x, the 
system pb 2 E is pure, so that S {E\x) = S {B 2 \x) for DR and S' {E\y) = S {A 2 \y) forRR. Thus, x (A : 
and x{B : E) become: 


(3) 


X{A:E) = S {PA 2 B 2 ) - S {pb2\x) 

x{B:E) = S{pA2B2)-T.yP{y)S{pA2\y) 

In practical experiments, we calculate the covariance matrix of correlated variables from 

randomly-chosen samples of measurement data. According to the optimality of collective Gaussian 
attacks [43,44], we therefore assume that the final state PA 2 B 2 ’ shared by Alice and Bob, is Gaussian to 
minimize the final secret key rates. If the entangled source is Gaussian, one can show that there exists 
a Gaussian channel mapping the initial state to the final state: this means that there exists a Gaussian 
attack that is optimal [43? ]. If the entangled source is non-Gaussian, it is an open question whether 
the optimal attack is Gaussian or not. However, whether Eve’s attack is Gaussian or not, we can always 
bound the information available to Eve by assuming the final state is Gaussian. 

Thus, the entropies S{pa 2 B 2 )^ J2xP (^) ^ {pb 2 \x) and Y.yP{y) S (pAiiy) can be calculated using the 
covariance matrices XA 2 B 2 characterizing the state PA 2 S 2 ’ 7 ^ 2 la; characterizing the state Pb 2 \x and 7 ^ 12 |j/ 
characterizing the state The Holevo quantities become: 

x(A-.E) = j:GiAp)-Gi^) 

‘-2' , ( 4 ) 

X'(B:-B) = EG(7i)-G(7^) 

1=1 

where G(a:) = (x-fl) log 2 (a: + 1 ) — a: log 2 X, Ai ^2 are the symplectic eigenvalues of the covariance matrix 
XA 2 B 2 and A 3 , A 4 are the symplectic eigenvalues of the covariance matrices Xb 2 \x and 7A2\y [3]- 

In particular, a practical example of the CV-QKD protocol with an untrusted source is the 
entanglement-in-the-middle protocol [37], in which the source is assumed to be a two-mode squeezed 
vacuum state. The latter numerical simulations are also based on this specific example. 
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2.2. Entanglement Swapping: Entanglement-Based Protocol with an Untrusted Relay 

The schematic of the entanglement-based CV-QKD protocol with an untrusted relay is shown in 
Figure 2a. This is inspired by the scheme of [31] and represents a modified entanglement-based version 
of the CV-QKD protocols proposed by [32-35]. It can be described as follows: 

Step 1: Alice and Bob both generate an Einstein-Podolsky-Rosen (EPR), states EPRi and EPR 2 , 
respectively, with variances Va and Vb and they keep modes A 2 and B 2 at their respective sides. Then, 
they send their other modes Ai and Bi to the untrusted third party (Charlie) through two different 
quantum channels with lengths Lac and Lbc- 

Step 2: Charlie combines the received two modes A'^ and B[ onto a beam splitter (50:50), where we 
label output modes of the beam splitter as C and D. Charlie then measures the x-quadrature of mode 
C and the p-quadrature of mode D using homodyne detectors and publicly announces the measurement 
results xctPd^o Alice and Bob through classical channels. After the measurements of modes C and D, 
the two initially independent modes A 2 and B 2 get entangled if channel noise is not too strong. 

Step 3: Bob displaces the mode B 2 to B^ by the operation D (/?) and gets psg = D (/?) (/5), 

where pb represents the density matrix of mode B, {3 = g {Xc + iPo), D {(3) = (a'^ and d 

are the creation and annihilation operators, respectively), and g represents the gain of the displacement. 
Then Bob measures the mode B^ to get the final data {xb,Pb} using heterodyne detection. Alice also 
measures the mode A 2 to get the final data {xa, Pa}, again using heterodyne detection. 

Step 4: Once Alice and Bob have collected a sufficiently large set of correlated data, they use an 
authenticated public channel to do parameter estimation from a randomly-chosen sample of final data 
from {xa,Pa} and {xb,Pb}- Then, Alice and Bob proceed with classical data post-processing to distil 
a secret key. The reconciliation can also be done in two ways: either DR or RR. 

Note that we can put the displacement operator at each side rather than placing it only at Bob’s side, 
which now makes the protocol symmetric (see Figure 2b). This symmetry allows the CV-QKD protocol 
with an untrusted relay to have a similar structure with the entanglement-in-the-middle protocol. In this 
modified protocol, Alice and Bob displace the modes A 2 and B 2 by the operators D (ai) and D ( 02 ), 
resulting in = D (ai) («i) and psg = D (« 2 ) (« 2 ), where «i = -gA {Xc - iPo) /2, 

<^2 = Qb {Xc + iPo) /2, and gA, gs represents the gain of the displacements at Alice’s and Bob’s side, 
respectively. 

Note that these protocols can completely defeat side-channel attacks provided that Alice and Bob 
use quantum memories in their private spaces, which is discussed in detail in [31]. From this point of 
view, this makes the CV-QKD protocol with an untrusted relay more secure. The secret key rate for 
these protocols against a collective attack is similar to Equation (1) and can be found in [32,33] in detail. 
See [34] for an unconditional security analysis against the most general coherent attacks. 
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Figure 2. (a) Entanglement-based CV-QKD protocol with an untrusted relay where the 
displacement operator is placed at Bob’s side, (b) Entanglement-based scheme where the 
displacement operator is placed at both Alice’s and Bob’s sides. 


3. Improvement Using Noiseless Linear Amplifiers 

In this section, we place two noiseless linear amplifiers (NLAs), one at each of Alice’s and Bob’s side, 
to improve the performance of the two entanglement-based CV-QKD protocols. We begin by introducing 
the NLA. 


3.1. Noiseless Linear Amplifier 


For Gaussian states, an NLA can, in principle, probabilistically increase the signal-to-noise ratio by 
increasing the mean values of the quadratures while keeping their variances at the initial level [38,45-48]. 
The amplification can be described by an operator C = g'^, where h is the number operator in the Fock 
basis. Such an operator maps jo;) into \ga) with a success probability P, i.e., 

C (la) («|) = P \ga) {ga\ + (1 - P) |0) (0|, (5) 


where g > 1 h the gain of the amplifier. Only the situations with successful amplification will be used 
to distil the final secret keys, while the others are discarded. 

In a practical experiment, the covariance matrix before passing through two NLAs takes the form 7, 
which is used to calculate the final secret key rates ( 7 A 2 B 2 for the entanglement distribution protocols 
(see Figure 1) and 7 A 3 B 3 for the entanglement swapping protocols (see Figure 2b)). Typically, 7 can be 
described by the normal form: 


7 = 


a -12 c- Oz 

C- Gz h- I 2 


( 6 ) 


where is the n x n identity matrix, and Gz = diag ( 1 ,- 1 ). 
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We then exploit the relationship between the covariance matrix 7 and the density matrix p in the Fock 
state basis [39]. The Husimi Q-function of the two-mode state can be described as: 

= (7) 

TT^ 

where R = {xa,Pa, xb,Pb) and F = (7 + Thus, we can find: 


A-h C-a, 
■Oz B ■ I2 


with new parameters A, B and C, after the application of an NLA on each side. In the Fock basis, the 
Husimi Q-function is a degenerating function of the density matrix elements. Thus, we can establish a 
relationship between elements of the covariance matrix F and the elements of the normalized density 
matrix ajk^im = Pjk,im/Poofio [49]. Then, the matrix F after the two NLAs becomes: 

\ {gl {A-\) + \)- h 9192C ■ Oz 1 

[ 9i92C-az {9l{B-\) + \)-hy 

where gi and §2 are the gains of the NLAs at Alice’s and Bob’s sides (pi = 1 or 5-2 = 1 means there is 
no NLA). Thus, the covariance matrix 7 ' after the NLAs can be obtained by: 


iNLA — (kATLA) ^ — Ia- 


( 10 ) 


This covariance matrix is used for the calculation of the final key rates in DR and RR, which are 
reduced according to the total amplification success probability Ptotai = PaPb\a, where Pa is the 
success probability of Alice’s NLA and Pb\a is the success probability of Bob’s NLA given that Alice’s 
amplification succeeded. Furthermore, considering the trade-off between the fidelity and the success 
probability of an NLA, a good estimate of the maximal expected success probability for one NLA is 
given by [50]: 


P = 


-,2N ' 


( 11 ) 


where N is the average photon number of the input state (ensemble) of the NLA. Such an NLA can 
amplify an input coherent \a) to the target output state \ga) with a relatively high fidelity. 


3.2. Entanglement-Based Protocol with an Untrusted Source 

Using the previous method, we can derive the final covariance matrix 7^353 to calculate the secret 
key rate. As shown in Figure 3, we consider a specific example of an entanglement-based protocol with 
an untrusted source: the EPR in the middle scheme [37]. This security analysis and latter numerical 
simulations of this scheme are based on the two independent entangling doner attacks. This is the most 
common example of a collective Gaussian attack [51]. Alice and Bob both add an NLA before their 
detectors, which here are assumed to be perfect for simplicity [38,45,46]. 
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Figure 3. Entanglement-in-the-middle protocol. Equivalent channels and squeezing: 
an Einstein-Podolsky-Rosen (EPR) state A sent through two Gaussian channels of 
transmittance Ti, T 2 and excess noise £ 1 , 62 , followed by two successful noiseless linear 
amplifiers (NLAs), has the same final covariance matrix with a state ? sent through two 
Gaussian channels of transmittance rp, r ]2 and excess noise ef, without two NLAs. 


We can look for equivalent parameters of an EPR state sent through two lossy and noisy Gaussian 
channels. The covariance matrix 7 '^^ (A, Ti, £ 1 , r 2 , £ 2 , 1 / 2 ) of the amplified state with an EPR 

parameter A passing through two channels of transmittance Ti,T 2 , and excess noise £i ,£2 followed 
by two gain efficiencies gi, § 2 , is equal to the covariance matrix yAB ^ 1 , Pi = 1, P 2 , P 2 = 1) of 
an equivalent system with an EPR parameter sent through two channels with parameters r)i, ef and r/ 2 , 
£ 2 , without using NLAs. These parameters are given by: 


l[(gf-l)(e-2)T-2 

' ( 5^2 ^ 

/ [(3?-1)s^-2 

4T3? 

. (9i-l)eT-2] 

’( 5^1 — l)- [(s^i —1)(^—2)6T—4(e—1)]+4 

-Hdi- 1) - 

4T3| 

- 2)£T 


__ 

r(3|-l).[(3|-l)(e-2)eT-4(e-l)]+4 


£! = £-l(d-^)(£- 2 ) sT 


( 12 ) 


These could be treated as physical parameters of an equivalent system if they satisfy the following 
physical constraints: 

f 0 <<j<l 

< 0 < r]i < l,£f > 0 (13) 

[ 0 < V2 < 1,4 ^ 0 

As shown in Equation (12), A only affects parameter c, and pi, ef, t ]2 and ef do not depend on A. 
Thus, the first condition is always satisfied if A is below a limiting value, given by: 


0 < A < 



(^^-i)£r -2 

-1)(£-2)T-2 



(^|-i)£r -2 

-1)(£-2)T-2’ 


(14) 


The last two conditions are satisfied if the excess noise £ is smaller than two and if the gain of the two 
NLAs is smaller than a maximum value, which depends on the channel parameters T and £: 


max _ max 

i/l — i/2 


I £ [T (£ — 2) + 2] — 2y^£ [T (£ — 2) + 2] 


Te (£ - 2) 


( 15 ) 
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Using the previous results, we consider the performance of the CV-QKD protocols with EPR in the 
middle by placing two NLAs, one at each output of the quantum channels. We calculate the secret key 
rate a function of distance d under four situations: without NLAs (gi = 1, g 2 = 1), with only an 

NLA at Alice’s side (g 2 = 1), with only an NLA at Bob’s side (gi = 1) and with two NLAs at both sides. 
The various parameters are chosen from typical experimental values [6]: we choose U = 1.7, /3 = 0.948 
and £ = 0.002 (where the shot noise variance is normalized to one). The transmittance T = 10““^^/^°, 
where o = 0.2 dB/km is the loss coefficient of the optical fibres and d is the length of the quantum 
channel. The total success probability of using two NLAs for the CV-QKD protocols with EPR in the 
middle is Ptotai = 1/ > where Na = T {V - 1 + e) + 1, Nb\a = T (U' - 1 + s) + 1 . 

Here, V is the variance of the equivalent EPR when Alice’s amplification succeeds, which is given by 
V' = {1 + <;^)/(l - provided g 2 = 1. 

In our analysis, there are eight protocols that depend on Alice’s and Bob’s measurements (four 
possibilities) and reconciliation methods (two possibilities, DR or RR). These eight CV-QKD protocols 
can be divided into four groups whose secret key rate and maximal transmission distance are the 
same [37]. When we move the entanglement source into Alice’s side, these eight protocols correspond 
to the entanglement-based version of the eight primary prepare-and-measure CV-QKD protocols, i.e., 
the protocols where Alice and Bob use homodyne detection corresponding to the protocol of [53]; the 
protocols where Alice uses heterodyne detection and Bob uses homodyne detection correspond to the 
protocol of [7,8]; the protocols where Alice uses homodyne detection and Bob uses heterodyne detection 
correspond to the protocol of [54,55]; the protocols where Alice and Bob use heterodyne detection 
correspond to the protocol of. [9]. 

Our simulation results are shown in Figures 4 and 5. We find that the performance of the CV-QKD 
protocols is improved by placing one NLA at each side and choosing the two gain efficiencies as 
9i = 92 = 1-4. The NLAs enhance the maximal transmission of the protocol, in which Alice is 
using heterodyne detection and Bob is using homodyne detection with DR, from 17.0 km to 31.6 km. 
Furthermore, we also find that if we only put an NLA at either Alice’s or Bob’s side, the performance of 
the protocols can also be improved. For instance, placing an NLA at the non-reconciliation side (Alice’s 
side for RR protocols and Bob’s side for DR protocols) has a greater improvement than placing it at 
the other side. This is because when adding an NLA only at one side (suppose it is on Alice’s side), 
according to Equation (12), the covariance matrix after the application of the NLA has the feature that 
Alice’s equivalent variance is greater than Bob’s variance. If considering Alice’s part as the reconciliation 
part, it is similar to the one-way CV-QKD protocol with DR; while, if considering Bob’s part as the 
reconciliation part, it is similar to the one-way CV-QKD protocol with RR. In one-way protocols, 
the RR protocol usually has a longer transmission distance than the DR protocol. Therefore, in our 
protocols, placing an NLA at the non-reconciliation side is better than placing it at the reconciliation 
side. Obviously, the optimal performance of the protocols is achieved by placing two NLAs at each side. 
However, if we want to reduce the cost and expense and only have one NLA in the deployment, we need 
to place it at the correct side to have the greatest improvement. 


10 
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Figure 4. Improvement of the CV-QKD protocols with entanglement-in-the-middle. A 
comparison among the secret key rates for the protocols where (left panel) Alice uses 
homodyne detection and Bob uses homodyne detection and DR(equivalent to Alice using 
homodyne detection and Bob using homodyne detection and RR); and (right panel) Alice 
uses heterodyne detection and Bob uses homodyne detection and DR (equivalent to Alice 
using homodyne detection and Bob using heterodyne detection and RR), under the following 
situations: no NLAs (pi = 1, §2 = 1), using an NLA at Alice’s side {§2 = 1), using an 
NLA at Bob’s side {gi = 1) and using two NLAs at both sides. Here, we use the realistic 
parameters: V = 1.7, /5 = 0.948, e = 0.002 and Ptotai = 1/ 



Figure 5. Improvement of the CV-QKD protocols with entanglement-in-the-middle. A 
comparison among the secret key rates for the protocols where (left panel) Alice uses 
homodyne detection and Bob uses heterodyne detection and DR (equivalent to Alice using 
heterodyne detection and Bob using homodyne detection and RR); and (right panel) Alice 
uses heterodyne detection and Bob uses heterodyne detection and DR (equivalent to Alice 
using heterodyne detection and Bob using heterodyne detection and RR), under the following 
situations: no NLAs (gi = 1, g 2 = 1), using an NLA at Alice’s side (g 2 = 1), using an 
NLA at Bob’s side {gi = 1) and using two NLAs at both sides. Here, we use the realistic 
parameters: V = 1.7, /5 = 0.948, e = 0.002 and Ptotai = 1/ 
















































Entropy 2015 , 17 


11 


Furthermore, as proven in [39,40], the physical implementation of the NLA could be replaced by a 
suitable data post-processing (Gaussian post-selection) after the measurement, although provided that 
certain conditions are met [52]. Thus, in such cases, we would not need to implement the physical 
implementation of the NLA, which requires single-photon addition and subtraction, or an auxiliary 
source of single photons and multiphoton interference [39,40]. 

3.3. Entanglement-Based Protocol with an Untrusted Relay 

The improvement seen in the previous section can also be employed in the modified CV-QKD 
protocol with an untrusted relay. The modified CV-QKD protocol with an untrusted relay is shown 
in Figure 6 where we place an NLA at both Alice’s and Bob’s sides. As illustrated in Figure 7a, the 
modified entanglement-based protocol can increase the maximal transmission distance when we choose 
1/ = 14 = 14 = 1.7, /3 = 0.948, s = ei = S 2 = 0.002, pa = (V-hs) + 2(l- 4)], 

Pb = \/{V^ — 1)/[2T2 {V 3- s) 3-2 (1 — T 2 )]. Under these simulation parameters, the modified 
entanglement-based protocol in the symmetric case (the distance from Alice to Charlie Lac is equal 
to the distance from Bob to Charlie Lbc) can successfully distribute secret keys under such conditions. 
Then, using the same method as above, we place an NLA at each side to improve its performance; we 
find an improvement when we set the two gain efficiencies as gi = 92 = 1-8. The NLAs enhance the 
maximal transmission distance of the protocol from 1.6 km to 5.3 km in the symmetric case. 



Figure 6. Entanglement-based scheme of the modified CV-QKD protocol with an untrusted 
relay, where a displacement operator D is placed at both Alice’s and Bob’s sides and the two 
NLAs are placed before the measurement devices. 


Furthermore, for DR, we also find that when Charlie’s position is close to Alice, the total maximal 
transmission distance Lab will increase to a relatively longer distance. Thus, we study the performance 
of the asymmetric case where Lac 7 ^ Lbc- As illustrated in Figure 7b, the total maximal transmission 
distance increases when Lac decreases. In the asymmetric case, the performance of the modified 
CV-QKD protocol is also improved by placing two NLAs, one at each side. The maximal total 
transmission distance of the modified protocol using two NLAs, with gain efficiencies gi = §2 = 1-8, 
is enhanced from 17.5 km to 25.2 km in the most asymmetric case (i.e.. Lac ~ 0 km). Here ‘0 km’ 
indicates that the transmission distance from Alice to Charlie is very short but not exactly zero. In 
fact, even when Charlie is at Alice’s side, there still exists a distance between Alice’s laser and the 
beamsplitter. Therefore, in the numerical simulation although we assume the channel transmittance is 
Ti = 1 , the excess noise £1 still exists, and is £1 = 0 . 002 . 
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Note that the sources for Alice and Bob are EPR states. Thus, the protocols can remove side-channel 
attacks, as discussed in [31], which makes the CV-QKD protocol with untrusted relay more secure. 
Finally, we also find that if we only put an NLA at Alice’s or Bob’s side, the performance of the protocols 
can also be improved. This is the same conclusion as before: placing an NLA at the non-reconciliation 
side (Alice’s side for RR protocols and Bob’s side for DR protocols) has a greater improvement than 
placing it at the other side. 



Figure 7. Improvement of the modified CV-QKD protocol with an untrusted relay in (a) the 
symmetric case (i.e.. Lac = Lbc) and (b) the asymmetric case {i.e.. Lac ^ Lbc)- A 
comparison among the secret key rates in DR under the following situations: no NLAs 
{gi = 1, §2 = 1), using an NLA at Alice’s side (§2 = 1), using an NLA at Bob’s side 
(gi = 1) and using two NLAs one at each side. Here, we use the realistic parameters: 
1(4 = Lb = 1.7, /3 = 0.948, £ = 0.002 and Ptotai = 1/ 


4. Conclusion 

In this paper, we have discussed how to improve the performance of two entanglement-based 
continuous-variable QKD protocols using noiseless linear amplifiers. The first scheme was an 
entanglement distribution protocol: continuous-variable QKD protocols with an untrusted source, where 
the entangled source is generated by a third party, but may have actually been created or controlled by 
the eavesdropper. The second scheme was an entanglement swapping protocol: entanglement-based 
continuous-variable QKD protocol with an untrusted relay. 

By inserting two noiseless linear amplifiers, one at each of Alice’s and Bob’s side, simulation results 
show that the proposed method can increase the maximal transmission distances of both protocols in the 
experimentally-feasible regime of small entanglement, corresponding to small modulation. In fact, in 
certain situations, we see a doubling of the allowed secure transmission distances. Furthermore, it is also 
found that placing only one NLA at the non-reconciliation side (Alice’s side for reverse reconciliation 
protocols and Bob’s side for direct reconciliation protocols) has a greater improvement than placing it at 
the other corresponding side. 

Future investigations will involve the analysis of the protocols against more general two-mode 
Gaussian attacks, which are coherent between the two channels connecting the remote parties with the 
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middle source or relay. In fact, as pointed out in [34], the unconditional secret-key rate of the relay-based 
protocol must be derived in the presence of such attacks, which may outperform the collective one-mode 
Gaussian attacks (based on the use of independent entangling doners). 
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